PkgRadar

npm · registry.npmjs.org

claude-opencode-viewer

Install Lifecycle Remote Or Exec: postinstall="node -e \"console.log('\\n✅ claude-opencode-viewer 安装成功!\\n\\n使用方法:\\n - 全局启动:cov\\n - 或通过 npm 启动:npx cov\\n')\""

Why PkgRadar flagged 2.6.56

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"console.log('\\n✅ claude-opencode-viewer 安装成功!\\n\\n使用方法:\\n - 全局启动:cov\\n - 或通过 npm 启动:npx cov\\n')\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.56High risk352026-06-10
2.6.55High risk352026-06-10
2.6.54High risk352026-06-10
2.6.53High risk352026-06-10
2.6.50High risk352026-06-10
2.6.51High risk352026-06-10
2.6.52High risk352026-06-10

Block this in CI

PkgRadar gates claude-opencode-viewer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]